3 ms·
> So you cannot use HTTPs to prove to a third party a response or a request when using client certificates is genuine. HTTPS is not sufficient for such third-p
by speedplane 7y ago
> So you cannot use HTTPs to prove to a third party a response or a request when using client certificates is genuine.
HTTPS is not sufficient for such third-party exchange, but they are necessary.
If you (say "System 1") ask for a twitter feed from an intermediary (say "System 2"), which in turn scrapes the data from twitter itself (say "System 3"), then HTTPS can indeed help. You can't rely on any hash or signature produced by System 2, because they could modify the data and make up a new hash. Instead, you would need to rely on the hash from System 3, to confirm that what you received from System 2 is authentic. Only tools like HTTPS, with their pre-installed security certificates, can do that.